---
# source: blog-content: posts/en/vmware-security-advisory.md
# route:  /en/insights/vmware-security-advisory/
title: VMware Security Advisory
date: 2024-09-18
author: daniel-stadelmann
locale: en
summary: Broadcom has disclosed a new vulnerability, covered by VMware Security Advisory 2024-0019. The issues are rated 7.5 to 9.8 on the CVSS scale.
capabilities: [security]
vendors: [vmware]
migrated: 2026-08-24
translationReviewed: false
draft: false
---

Broadcom has disclosed a new vulnerability. It is covered by VMware Security Advisory 2024-0019 and the issues are rated 7.5 to 9.8 on the CVSS scale. The most severe one (CVSS 9.8) should be closed with the available update as soon as possible.

## VMSA-2024-0019

The published vulnerability ([CVE-2024-38812](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38812)) lets an attacker with network access to the vCenter appliance perform remote code execution. The second one ([CVE-2024-38813](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38813)) lets an attacker with network access to the vCenter appliance obtain root rights through privilege escalation. Only vCenter is affected. Further detail and the fixed version are at [Broadcom](https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968).

Broadcom reports no known attacks so far. With the vulnerabilities now published that can change within hours. Both soulTec and Broadcom recommend patching the affected systems immediately. If you need a hand, [we are glad to help](https://soultec.ch/contact-us/).
